WP Fusion Lite WordPress 插件在 3.48.0 版本之前,未对其两个管理端 AJAX 处理器执行权限检查,导致任何已认证的订阅者都可以读取其他用户的电子邮件地址,并触发跨用户 CRM 重新同步。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Unknown | WP Fusion Lite | 0 ~ 3.48.0 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-96173 | Payments for Hubtel < 1.0.2 - Unauthenticated Order Key Disclosure via IDOR | |
| CVE-2026-96200 | Payments for Hubtel < 1.0.2 - Unauthenticated Payment Confirmation Forgery via Delayed Pay | |
| CVE-2026-96255 | Payments for Hubtel < 1.0.2 - Unauthenticated Payment Gateway Credentials Disclosure via D | |
| CVE-2026-89296 | Pro Like Button < 2.0 - Unauthenticated SQLi via 'postid' Parameter | |
| CVE-2026-87973 | If-So Dynamic Content 1.9.9 - 1.10.1 - Editor+ Stored XSS via Conversion Name | |
| CVE-2026-87970 | If-So Dynamic Content 1.8 - 1.10.1 - Reflected XSS via render_ifso_shortcodes | |
| CVE-2026-92412 | Five Star Restaurant Reviews < 2.3.14 - Reflected XSS | |
| CVE-2026-90974 | WP Fusion Lite 3.37.14 - 3.47.14 - Unauthenticated CRM Integration Settings Update | |
| CVE-2026-19253 | Cache Enabler < 1.8.17 - Unauthenticated Arbitrary File and Directory Deletion via cache_e | |
| CVE-2026-81739 | Paytm Payment Gateway < 2.8.9 - Unauthenticated Stored XSS via Payment Callback | |
| CVE-2026-81809 | Paytm Payment Gateway < 2.8.9 - Unauthenticated SQLi via Payment Callback | |
| CVE-2026-86610 | Download Manager < 3.3.71 - Author+ Stored XSS via Package Icon | |
| CVE-2026-101148 | BackupSheep <= 1.8 - Unauthenticated Arbitrary File Deletion and Backup Exfiltration via E | |
| CVE-2026-101147 | Featured Image from URL (FIFU) Free & Premium - Administrator Account Creation via CSRF |
No comments yet